冷气水 · Lengqishui
Data & third-party services / 数据与第三方服务
A code-based inventory; final store declarations must match the shipped build and live configuration.
Publication status / 发布状态
Draft / 准备中 — the marked operational and policy items are not yet finalized. This is not a claim that the native apps are available or ready for store review.
Collected or processed in existing flows
Account IDs, email, nickname, password hashes and verification/session data; optional WeChat identifiers/avatar; user answers and writing; microphone recordings when used/uploaded; transcripts and automated scores; practice and learning history; community content and reports; guest IDs, page/learning events, User-Agent, referral data and IP-related records. Public profile/leaderboard/community visibility is distinct from service-provider processing.
Prepared registration records
The planned first native release permits accounts from age 16. Users aged 16–17 will be asked to confirm permission from a parent or guardian. The prepared registration control records an age band and acknowledgements rather than a full date of birth or a parent's identity. This is a self-declaration, not verified parental consent. The control remains disabled while the policy is a draft; existing accounts have not been assigned an age by assumption. Once enabled with a reviewed policy, the new-account record includes the account link, declared age band, policy version, terms acceptance, privacy acknowledgement, guardian confirmation when required, and a confirmation timestamp. These prepared records must be covered by retention and account deletion; they are not evidence that the current deployment collects them.
Current storage and purpose
Backend relational tables hold accounts, attempts, learning and community records. Recordings are written to server storage. Browser/device storage holds settings and some local learning/audio-cache data. Scoring processes answers to provide learning feedback; account and email services handle authentication; analytics and security records support operation and product analysis. TODO — establish and verify retention, backup and complete deletion handling.
Hosting locations
Production checks on 27 September 2026 located the main website/API, account database and recording storage on Alibaba Cloud in Hangzhou, mainland China, and the speech-scoring and verification-relay services on Tencent Cloud in Shanghai, mainland China. These services therefore process data outside Canada. This does not establish where every other provider or subprocessor keeps its copies.
Company correspondence provider
If you email our support or privacy/legal addresses, Zoho Mail processes your sender address, message content and any attachments as our company mailbox provider. We use this correspondence to respond to your enquiry. Do not send passwords, verification codes or unnecessary sensitive information. This is not a claim that account verification or uploaded practice recordings are routed through the company mailbox.
Product services and relay processing
The deployed service uses Brevo to deliver verification emails and Cloudflare Turnstile for abuse prevention. Requests pass through a relay on the speech-scoring host, which can process recipient addresses and message content, including verification codes, as well as challenge tokens and remote IP addresses. Company support mail uses a separate mailbox provider. WeChat web sign-in is disabled in the checked deployment; its optional integration remains in the code. The checked API selects the speech-scoring service hosted in Shanghai. MaxMind provides a local IP-geolocation database if configured. TODO — confirm other providers' and subprocessors' locations and contractual handling; the company mailbox does not determine the product's verification-email or recording route.
Not established by this audit
No ordinary phone-entry flow, GPS collection, advertising SDK, card-data collection, Apple IAP or Google Play Billing implementation was identified. No cloud AI upload is inferred from the word “AI”. No dedicated crash SDK was identified; server/access logs and SDK/runtime behavior still require review. Native SDK identifiers and permissions must be inspected in the actual IPA/AAB.
Store disclosure work remaining
TODO — confirm which data is linked to accounts, which is optional, retention/deletion behavior, encryption across every hop, SDK collection and provider terms. Map the verified inventory to Apple App Privacy and Google Play Data Safety categories; do not equate service-provider processing with every store definition of “sharing”. Resolve the account-deletion gap before submission.